> Markdown version of [/jobs/ext/458012-platform-engineer-security](https://www.wearedevelopers.com/jobs/ext/458012-platform-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Engineer, Security - **Company:** DECAGON, LLC - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Salary:** $200,000.0 - $330,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Software Applications, Software as a Service, Static Program Analysis, Code Review, Customer Data Management, Cursor (Graphical User Interface Elements), Dynamic Program Analysis, Machine Learning, Open Web Application Security, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Google Cloud, Software Security, Virtual Agents, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e2c909005415e813 ## About the Role Do you have experience in Web Application Security Testing?, * Have 3-5 years of hands-on application security engineering experience * Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications * Experience implementing application security testing tools and integrating security into CI/CD pipelines * Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks * Proven track record working with engineering teams to remediate security findings while balancing security and business requirements Even better * Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections * Background with large-scale, multi-tenant SaaS applications handling sensitive customer data * Familiarity with Google Cloud application security services and container security best practices * Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective * Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar ## Description Our mission is to provide magical support experiences - ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy., Lead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization. In this role, you will * Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management. * Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment * Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications * Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling * Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity * Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)